HIGH 7.1 NVD
CVE-2026-73616
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms.
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
References
- https://github.com/openremote/openremote/security/advisories/GHSA-rc23-4mmm-4fx9
- https://www.vulncheck.com/advisories/openremote-notification-delete-cross-realm-insecure-d
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.